using System;
using System.Collections.Generic;
using System.Text;
using Microsoft.Practices.EnterpriseLibrary.Data.Sql;
using FinanceStats.Common;
using System.Data;

namespace FinanceStats.DAL
{
    public static class UserDAO
    {
        public static int CheckLogin(string username, string password)
        {
            int res = -1;
            string select = String.Format("select userid from [acs].[dbo].[user] where username = '{0}' and password = '{1}'", username, password);
            SqlDatabase db = new SqlDatabase(AppSettingsHelper.GetWebConfigValue(Constants.ACSConnectionString));
            object id = db.ExecuteScalar(CommandType.Text, select);
            res = id == null ? -1 : (int)id;
            return res;
        }
    }
}
